CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-04
Junior Member
 
Join Date: 2007-10-02
Posts: 10
Rep Power: 0
osterber has an average reputation (10+)
Default VPN-1 UTM, SmartCenter and logging

I have a question about a new install of Checkpoint.

I'm licensing the VPN-1 UTM software. We are a relatively small and straightforward site -- a single internal subnet, a DMZ, and a handful of SecureRemote clients.

My plan is to install the firewall module on dedicated hardware. Then, it sounds like I can get away with installing a SmartCenter server onto our existing VMWare server to manage the policies, etc.

My question is -- where do all of the logs end up? Do I end up with the firewall logs being stored on the firewall hardware? Or do they necessarily get stored on the SmartCenter server? (Since the fw hardware is dedicated hardware, I'll have gobs of disk space. Since the SmartCEnter server is hopefully under VMWare, I'd like to keep disk space to a minimum.)

Thanks.

-Rick
Reply With Quote
  #2 (permalink)  
Old 2007-10-04
Senior Member
 
Join Date: 2007-06-04
Posts: 1,071
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: VPN-1 UTM, SmartCenter and logging

The logs normally are sent to the SMARTCenter.

The logs will store locally if they cannot contact the SMARTCenter, and then forward up when connectivity is restored.

I would point out however that Check Point don't officially support SMARTCenter in a virtual environment, even though it does actually work.
Reply With Quote
  #3 (permalink)  
Old 2007-10-05
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: VPN-1 UTM, SmartCenter and logging

From what you describe, maybe you should install both management and firewall in the same box. I'd probably suggest using SPLAT too.

Any server you can get nowadays (or even an old one) will be able to cope easily. Just be careful with NICs and RAID controllers, to make sure they will be picked up.
Reply With Quote
  #4 (permalink)  
Old 2007-10-05
Junior Member
 
Join Date: 2007-10-02
Posts: 10
Rep Power: 0
osterber has an average reputation (10+)
Default Re: VPN-1 UTM, SmartCenter and logging

I'm thinking you might be right. What was attractive of having a separate SmartCenter was that licensing becomes easier when rolling out a new firewall. (I.e., I have an existing NG firewall on old hardware that I'm completely replacing... but there's a bit of a leap of faith at the final moment to swap the IP addresses, etc.)

I'm definitely on SPLAT. I've got a Dell server that is completely on the hardware list.

-Rick
Reply With Quote
  #5 (permalink)  
Old 2007-10-08
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: VPN-1 UTM, SmartCenter and logging

If you can, you really do want SmartCenter on a separate box. It will save you a lot of headaches if you ever expand.

You might also want to look at a UTM-1 450 if you do want to run central.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:35.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0